> Markdown version of [/jobs/ext/3282930-information-system-security-manager-iii](https://www.wearedevelopers.com/jobs/ext/3282930-information-system-security-manager-iii). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Manager III - **Company:** ORBIS INC. - **Location:** San Diego, CA, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Agile Methodology, Configuration Management, Cyber Security, Information Systems, Identity and Access Management, Information Security Management, SARS Software Products, Navsea, Information Technology, Process Control Systems, Scap Compliance Checker, Devsecops, Plan of Action and Milestones - **Published:** September 30, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9205346/information-system-security-manager-iii ## About the Role * Clearance: Must possess an active, TS/SCI and be a United States citizen. * Education: Master's degree in Computer Science, Information Technology, Cybersecurity, or an equivalent STEM discipline from an accredited university. (A Bachelor's degree with two additional years of highly specialized experience may be considered). * Experience: A minimum of eight (8) years of dedicated cybersecurity experience coordinating with various organizational levels to manage and oversee information security program implementation. * Leadership Experience: Proven experience managing cyber strategies, infrastructure, policy enforcement, emergency planning, and security awareness programs. * Certifications: Must possess and maintain a current DoD 8140/8570 IAM Level III certification (e.g., CISSP, CISM, CISO, GSLC, or CASP+ CE). * Comprehensive knowledge of NIST Special Publication 800-53 security controls, NIST 800-37 RMF guidelines, and Navy/NAVSEA specific cybersecurity business rules. * Extensive hands-on experience utilizing eMASS for package submission and continuous monitoring., * Experience working directly with Navy afloat platforms, hull, mechanical and electrical (HM&E) systems, or industrial control systems (ICS). * Experience acting as an ISSM for a Navy command or echelon II/III organization. * Familiarity with DevSecOps methodologies and integrating RMF into agile software development lifecycles. ## Description Position Overview ORBIS requires a highly skilled Information System Security Manager III (ISSM III) to provide senior technical leadership for the NSWC Corona CCAM contract. The ISSM III will act as the principal advisor on all matters, technical and otherwise, involving the security of assigned information systems. This key personnel position is critical to ensuring that ORBIS effectively manages and implements the RMF A&A processes for complex Navy systems, ensuring they achieve and maintain their Authority to Operate (ATO). Core Responsibilities & Technical Execution: * Take ownership of the cybersecurity posture for assigned NSWC Corona enclaves, networks, and Platform IT (PIT) systems. * Lead the development, submission, and maintenance of complete RMF A&A packages in accordance with DoD Instruction 8510.01 and Navy RMF Process Guides. * Oversee the work of assigned Information System Security Officers (ISSOs) and System Administrators to ensure the continuous implementation of security controls. * Develop, review, and approve critical cybersecurity documentation, including System Security Plans (SSPs), Security Assessment Reports (SARs), Risk Assessment Reports (RARs), and Configuration Management Plans. * Act as the primary technical liaison between system owners, the Navy Security Control Assessor (SCA), and the Authorizing Official (AO) for all package reviews and continuous monitoring activities. * Manage the Enterprise Mission Assurance Support Service (eMASS) records for assigned systems, ensuring all artifacts, test results, and control implementations are accurate and current. * Direct the formulation and management of complex Plan of Action and Milestones (POA&M) entries, working with engineering teams to identify mitigation strategies, resource requirements, and timeline estimates. * Lead the response to cybersecurity incidents, directing forensic data collection, reporting to higher echelons, and implementing corrective actions to prevent recurrence. * Conduct high-level reviews of Assured Compliance Assessment Solution (ACAS) scans, Security Technical Implementation Guide (STIG) checklists, and SCAP Compliance Checker (SCC) results. * Enforce strict configuration management policies, reviewing and approving all proposed system changes, hardware additions, and software updates through the local Change Control Board (CCB). * Develop and deliver cybersecurity awareness training and briefings for system users, privileged users, and leadership. * Monitor Information Operations Conditions (INFOCONs), Cyber Tasking Orders (CTOs), and Information Assurance Vulnerability Alerts (IAVAs) to ensure rapid compliance and reporting. ## Related Videos - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)